An active worm in the npm JavaScript repository is spreading across more than 2,000 versions of 444 unique packages after a threat actor compromised the source or release credentials for widely used ...
The Mini Shai-Hulud worm has resurfaced in one of its largest single-registry waves to date, hitting hundreds of npm packages tied to the AntV data visualization ecosystem in a coordinated burst ...
On March 31, 2026, unknown attackers managed to publish two backdoored Axios npm packages after gaining access to a maintainer’s npm account. The malicious versions introduced a hidden dependency ...